Horizon Alert
Summary of the vulnerability and why it matters
This vulnerability affects a WordPress plugin that handles user logins and single sign-on. It could allow unauthorized access to user accounts, including administrator accounts, by misusing identity assertions. The primary concern is to confirm if this plugin is in use and exposed externally.
- Misused login information allows account takeover.
- Enables single sign-on impersonation risks.
- Confirm plugin use and external exposure.
Attack Path
How an attacker could exploit the issue
An attacker with low privileges on a WordPress site can impersonate other users, including administrators, by exploiting a flaw in how the WP OAuth Server plugin handles identity assertions. This allows them to authenticate as any user to applications relying on the site for single sign-on.
- Requires low-privileged user access.
- Vulnerability triggered during token exchange.
- Risk of full account takeover.
Live Threat
Current exploitation, exposure, and threat context
When supported by the advisory, this vulnerability could allow a user with the Subscriber role or higher to obtain a signed identity assertion for another user, potentially including an administrator. This assertion could then be used to authenticate as that other user to any application utilizing the site for single sign-on.
- Administrator account access.
- Impersonation via identity assertion.
- Unauthorized application access.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability impacts WordPress sites utilizing the WP OAuth Server plugin for OpenID Connect single sign-on. Ownership likely resides with the website's application or platform team, supported by the vendor management team for plugin updates. The immediate first step is to identify all instances of the affected plugin, determine which are internet-facing and critical, and confirm the accountable owner for remediation.
- Application owners should prioritize this.
- Verify internet-facing instances and impact.
- Plan remediation based on identified risk.